Apache permission denied when binding to address
まだ誰も着手していません。
評価
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 初心者へのやさしさ
- 35/100
- issue の種類
- バグ
- 明瞭さ
- 説明が足りない
- 活発さ
- 停滞
- 技術スタック
- apache, aws, helm, kubernetes, postgresql
- 領域
- cloud, devops, infrastructure
調査の方向性
提供された values.yaml から始め、特に nextcloud.securityContext、containerPort、および Helm chart によって生成される Kubernetes deployment を確認してください。EKS で Apache の起動失敗を再現し、rendered されたセキュリティ設定を追跡してください。報告された non-root のストレージ設定を維持したまま chart が正常に起動すれば完了です。
索引モデルが issue の本文から書いたものです。
説明
Describe your Issue
Nextcloud doesn't start because of apache not being able to bind to port 80. I tried to set the sysctls option, I tried runAsNonRoot false, changing the containerPort to a non privileged port, but nothing works.
I'm using a traefik reverse proxy as an ingress controller which is confgured correctly(it is used for all our production stacks).
Logs and Errors
| Initializing nextcloud 30.0.6.2 ... │
│ New nextcloud instance │
│ Installing with PostgreSQL database │
│ => Searching for scripts (*.sh) to run, located in the folder: /docker-entrypoint-hooks.d/pre-installation │
│ Starting nextcloud installation │
│ Nextcloud was successfully installed │
│ Setting trusted domains… │
│ System config value trusted_domains => 1 set to string xxxxxxxxxxxxxxx │
│ => Searching for scripts (*.sh) to run, located in the folder: /docker-entrypoint-hooks.d/post-installation │
│ Initializing finished │
│ => Searching for scripts (*.sh) to run, located in the folder: /docker-entrypoint-hooks.d/before-starting │
│ AH00558: apache2: Could not reliably determine the server's fully qualified domain name, using 10.11.19.106. Set the 'ServerName' directive globally to suppress this message │
│ (13)Permission denied: AH00072: make_sock: could not bind to address [::]:80 │
│ (13)Permission denied: AH00072: make_sock: could not bind to address 0.0.0.0:80 │
│ no listening sockets available, shutting down │
│ AH00015: Unable to open logs
Describe your Environment
-
Kubernetes distribution: eks
-
Helm Version (or App that manages helm): helm v3.16.2
-
Helm Chart Version: 6.6.9
-
values.yaml:
image:
pullPolicy: Always
phpClientHttpsFix:
enabled: false
protocol: https
nextcloud:
host: xxxxxxxxxxxxxxxx
username: admin
password: xxxxxxxxxxxxxx
containerPort: 80
datadir: /var/www/html/data
securityContext:
runAsUser: 50002
runAsNonRoot: true
sysctls:
- name: net.ipv4.ip_unprivileged_port_start
value: "0"
objectStore:
s3:
enabled: true
accessKey: "xxxxxxxxx"
secretKey: "xxxxxxx"
ssl: true
port: "443"
region: "xxxxxxxxxxxxx"
bucket: "xxxxxxxxxxx"
# Extra config files created in /var/www/html/config/
# ref: https://docs.nextcloud.com/server/latest/admin_manual/configuration_server/config_sample_php_parameters.html#multiple-config-php-file
configs: {}
# For example, to enable image and text file previews:
# previews.config.php: |-
# <?php
# $CONFIG = array (
# 'enable_previews' => true,
# 'enabledPreviewProviders' => array (
# 'OC\Preview\Movie',
# ),
# );
internalDatabase:
enabled: false
externalDatabase:
enabled: true
type: postgresql
host: "aurora1.xxxxxxxxx.com"
user: xxxxxxxx
password: "xxxxxx"
database: xxxxxx
persistence:
enabled: true
storageClass: "efs-sc"
accessMode: ReadWriteOnce
size: 8Gi
livenessProbe:
enabled: false
initialDelaySeconds: 120
periodSeconds: 10
timeoutSeconds: 5
failureThreshold: 3
successThreshold: 1
readinessProbe:
enabled: false
initialDelaySeconds: 120
periodSeconds: 10
timeoutSeconds: 5
failureThreshold: 3
successThreshold: 1
startupProbe:
enabled: false
initialDelaySeconds: 120
periodSeconds: 10
timeoutSeconds: 5
failureThreshold: 30
successThreshold: 1
Additional context, if any
We're using NFS for persistance using AWS EFS, it works fine. We're using Aurora PostgreSQL as a database, it works fine too. I turned off the probes temporarily because the initialization lasts for 5-10 minutes.
I've set runAsUser: 50002 because that was the only way to make storage permissions work.
- 主要言語
- Go Template
- スター
- 536
- フォーク
- 316
- 平均マージ
- 4日 16時間
- マージ済み PR(30日)
- 2
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートあり
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
nextcloud/helm のほかの issue
-
No native support for REDIS_USER enviroment var対応中かも @jholmes802 が 1 日前に担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
-
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
-
nextcloud.openmetrics.allowedClients is silently ignored unless nextcloud.configs is set対応中かも @JanWelker が 17 日前に担当しました。 オープン
難易度 3/5 1〜2日 初心者へのやさしさ 78/100
-
External Redis not working: redis-session.ini: Permission denied対応中かも @antoinetran が 22 日前に担当しました。 オープン
難易度 3/5 1〜2日 初心者へのやさしさ 55/100
似ている issue
-
api: run samples
難易度 2/5 1〜3時間 初心者へのやさしさ 62/100
GoogleCloudPlatform/python-docs-samples#14633 ·
メンテナーはふだん 5 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
apache/iceberg-python#4093 ·
メンテナーはふだん 1 日以内に返信
-
enhancement exporter/awss3 needs triage
難易度 2/5 1〜3時間 初心者へのやさしさ 66/100
open-telemetry/opentelemetry-collector-contrib#51905 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
- P2: has workaround pkg: cloudflare triage: fix pending
難易度 2/5 1〜3時間 初心者へのやさしさ 65/100
withastro/astro#18319 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
gke-gcloud-auth-plugin accepts empty Edge Cloud access tokens対応中かも @riccardomenegazzo が今日担当しました。 オープンneeds-triage
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
kubernetes/cloud-provider-gcp#1386 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信